| Time & API |
Arguments |
Status |
Return |
Repeated |
1619936569.895625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00a50000
|
success
|
0 |
0
|
1619936569.895625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00b60000
|
success
|
0 |
0
|
1619936570.098625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
1376256
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x02480000
|
success
|
0 |
0
|
1619936570.098625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02590000
|
success
|
0 |
0
|
1619936570.176625
NtProtectVirtualMemory
|
process_identifier:
3272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e71000
|
success
|
0 |
0
|
1619936570.255625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
655360
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
8192
(MEM_RESERVE)
base_address:
0x00a90000
|
success
|
0 |
0
|
1619936570.255625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00af0000
|
success
|
0 |
0
|
1619936570.270625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009ba000
|
success
|
0 |
0
|
1619936570.270625
NtProtectVirtualMemory
|
process_identifier:
3272
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
8192
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x73e72000
|
success
|
0 |
0
|
1619936570.270625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009b2000
|
success
|
0 |
0
|
1619936570.473625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c2000
|
success
|
0 |
0
|
1619936570.567625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a65000
|
success
|
0 |
0
|
1619936570.567625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a6b000
|
success
|
0 |
0
|
1619936570.567625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a67000
|
success
|
0 |
0
|
1619936570.739625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c3000
|
success
|
0 |
0
|
1619936570.801625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
12288
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c4000
|
success
|
0 |
0
|
1619936570.817625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009cc000
|
success
|
0 |
0
|
1619936570.895625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04da0000
|
success
|
0 |
0
|
1619936570.895625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
49152
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04da1000
|
success
|
0 |
0
|
1619936571.083625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c7000
|
success
|
0 |
0
|
1619936571.380625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
8192
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009c8000
|
success
|
0 |
0
|
1619936571.473625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04dad000
|
success
|
0 |
0
|
1619936571.520625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a56000
|
success
|
0 |
0
|
1619936571.676625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x02591000
|
success
|
0 |
0
|
1619936571.755625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a5a000
|
success
|
0 |
0
|
1619936571.755625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00a57000
|
success
|
0 |
0
|
1619936571.942625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e0000
|
success
|
0 |
0
|
1619936571.942625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e1000
|
success
|
0 |
0
|
1619936571.973625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e2000
|
success
|
0 |
0
|
1619936572.005625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04dae000
|
success
|
0 |
0
|
1619936583.161625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e3000
|
success
|
0 |
0
|
1619936583.755625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04daf000
|
success
|
0 |
0
|
1619936583.755625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e4000
|
success
|
0 |
0
|
1619936584.005625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e5000
|
success
|
0 |
0
|
1619936584.067625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e6000
|
success
|
0 |
0
|
1619936584.067625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009cd000
|
success
|
0 |
0
|
1619936584.067625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f70000
|
success
|
0 |
0
|
1619936584.067625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f71000
|
success
|
0 |
0
|
1619936584.067625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009ca000
|
success
|
0 |
0
|
1619936584.067625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x009cb000
|
success
|
0 |
0
|
1619936584.083625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f80000
|
success
|
0 |
0
|
1619936584.098625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e7000
|
success
|
0 |
0
|
1619936584.114625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f81000
|
success
|
0 |
0
|
1619936584.348625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e8000
|
success
|
0 |
0
|
1619936584.348625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025e9000
|
success
|
0 |
0
|
1619936584.348625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x04f82000
|
success
|
0 |
0
|
1619936584.348625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025ea000
|
success
|
0 |
0
|
1619936584.364625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x025eb000
|
success
|
0 |
0
|
1619936584.395625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
327680
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
1056768
(MEM_RESERVE|MEM_TOP_DOWN)
base_address:
0x7ef40000
|
success
|
0 |
0
|
1619936584.395625
NtAllocateVirtualMemory
|
process_identifier:
3272
region_size:
4096
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x7ef40000
|
success
|
0 |
0
|